APT29 is a Russian state-sponsored cyber espionage threat actor associated with the Russian Foreign Intelligence Service (SVR). It is widely tracked under aliases including Cozy Bear, The Dukes, Midnight Blizzard, Nobelium, Dark Halo, SolarStorm, UNC2452, and Yttrium, though some reporting distinguishes specific clusters or campaign labels from the core intrusion set. The actor is known for long-term intelligence collection operations, stealthy tradecraft, and the use of custom malware families and tailored post-compromise tooling. APT29 has targeted government, public-sector, and other strategically significant organizations, and has been publicly linked to the 2020 SolarWinds compromise. Reported activity also includes credential theft operations against travelers through compromised hotel authentication infrastructure, indicating continued interest in espionage-oriented collection against individuals connected to higher-value targets. The group commonly gains initial access through spearphishing with malicious attachments and has also conducted supply-chain intrusion activity. After access, it uses PowerShell extensively for payload delivery, command execution, configuration discovery, defense evasion, remote task creation, and data exfiltration. Observed tooling and malware associated with the actor include CozyCar, SeaDuke, WellMess, SUNSPOT, SUNBURST, TEARDROP, and Raindrop, as well as Cobalt Strike in some operations. APT29 has also used mshta for script execution, scheduled tasks for persistence and lateral movement, Registry Run keys for persistence, browser credential theft, process and system discovery, and HTTP-based command-and-control and exfiltration. The actor has leveraged multiple command-line and native administrative utilities during post-exploitation and has used obfuscation and decoding techniques, including 7-Zip in SolarWinds-related activity. APT29 is assessed as a mature, highly capable intrusion set with a strong emphasis on operational security, custom malware development, persistence, credential access, and covert intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
41 malware families attributed to this actor across reporting.
36 additional families tracked in Mallory.
37 CVEs this actor has used in observed campaigns. 37 of them exploited in the wild.
A report published in December 2023 by Polish, British and American authorities stated that Nobelium operators had exploited CVE-2023-42793 since September 2023 on a large scale against servers hosting the JetBrains software developed by TeamCity.
The following are the vulnerabilities exploited by APT29. CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability.
The following are the vulnerabilities exploited by APT29. CVE-2019-11510: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability.
In a separate incident, SVR actors used CVE-2019-19781, a zero-day exploit at the time, against a virtual private network (VPN) appliance to obtain network access. Following exploitation of the device in a way that exposed user credentials, the actors identified and authenticated to systems on the network using the exposed credentials.
The following are the vulnerabilities exploited by APT29. CVE-2019-9670: Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference.
32 more CVEs tied to this actor tracked in Mallory.
629 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the parent cluster of Storm-2945 in the CaptiveCrunch example.
Referenced as the larger Russia-linked threat actor organization of which Storm-2945 is a sub-group.
Referenced as the parent threat group of Storm-2945, the Russia-linked actor behind the broader activity cluster associated with the CaptiveCrunch campaign.
Conducting the CaptiveCrunch credential theft campaign by manipulating DNS and HTTP traffic on captive portal networks at hospitality venues to redirect victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.